The Two Charts That Define the QVaR Thesis
The first chart separates the three dimensions of quantum financial exposure while connecting them to live institutional tokenization activity. The second shows the migration-readiness gap across the assessed programmes.
QVaR in 60 Seconds: Direct Answers
QVaR is an umbrella framework for measuring quantum-related financial exposure across three dimensions: Asset QVaR, Flow QVaR and Settlement QVaR.
$796.7B is modeled Asset QVaR: standing economic value governed by the scored quantum-vulnerable control surfaces in the 28-programme register.
Canton reports $6T+ processed monthly. Applying the report's current vulnerability factor of 0.80, with no credited network-wide deployed PQ mitigation, gives $4.8T+/month of modeled Flow QVaR. It is throughput exposure, not $4.8T of unique assets.
Settlement QVaR estimates how much value can become economically exposed during a defined compromise, detection, containment and settlement window after accounting for control scope, limits, DvP/netting, reversibility and loss severity.
No. Migration Readiness Score is reported separately. A plan or roadmap improves readiness but does not make today's classical cryptographic control safer.
No. Asset QVaR is measured in dollars at a point in time; Flow QVaR is measured in dollars per day or month. They are complementary but dimensionally different.
The benchmark covers 15 networks in source order: EternaX, Zcash, Canton, Ethereum, Solana, Arc, Tempo, Hyperledger Besu, Stellar, Starknet, Sui, Aptos, NEAR, Algorand and XRP Ledger.
Inventory cryptographic control surfaces, calculate Asset and Flow QVaR, then use private transaction/finality/control data to calculate Settlement QVaR and prioritize remediation.
Why Institutional Digital Assets Need a Quantum Risk Metric
Institutional digital-asset infrastructure already governs hundreds of billions of dollars in stablecoins, tokenized funds, custody balances, and on-chain settlement flows. The larger strategic context is much bigger: SIFMA reports $157.8 trillion of global equity market capitalization and $160.7 trillion of global fixed-income securities outstanding for 2025 — a combined $318.5 trillion capital-market base. This report does not assume all $318.5T will move on-chain. It treats that figure as the addressable financial-market base against which tokenization is expanding, making cryptographic resilience a market-infrastructure question rather than a crypto-only question. Primary source: SIFMA 2026 Capital Markets Fact Book findings.
The policy timeline requires precision. NIST IR 8547 remains an Initial Public Draft: it proposes deprecation after 2030 for 112-bit ECDSA/RSA parameter sets and disallowance after 2035, while 128-bit-or-higher ECDSA and EdDSA are proposed to be disallowed after 2035. Executive Order 14412 directly requires Federal high-value assets and high-impact systems to transition key establishment by December 31, 2030 and digital signatures by December 31, 2031, and separately directs the FAR Council to propose requirements for covered contractors. These dates are important institutional planning signals; they are not a universal statutory deadline for every private blockchain operator. FIPS 140-2 validated modules remain on the active CMVP list through September 21, 2026 and are scheduled to move off the active list on September 22, 2026. NIST IR 8547 · EO 14412 · NIST CMVP.
Institutional risk committees already separate stocks, flows and settlement exposures in other risk domains. QVaR applies the same discipline to quantum cryptographic risk: Asset QVaR measures standing value, Flow QVaR measures quantum-critical throughput over a defined period, and Settlement QVaR estimates the value economically exposed during an institution-specific attack and settlement window. Flow QVaR is network-agnostic: any network carrying economic transactions can be scored once a comparable flow class and time horizon are defined.
$318.5T Capital Markets Are Moving Onto Cryptographic Rails
SIFMA reports $157.8T of global equity market capitalization and $160.7T of global fixed-income securities outstanding for 2025 — $318.5T combined. This is addressable capital-market context, not a claim that $318.5T is already tokenized or quantum-exposed.
The relevant signal is that real institutional infrastructure is already moving securities, collateral, funds and settlement workflows onto cryptographic rails. Tokenization forecasts reinforce the direction of travel: BCG’s 2026 middle-of-the-road scenario estimates $14T by 2030 and $55T by 2035; Standard Chartered and Synpulse project $30.1T by 2034. These are forecasts, not current on-chain value.
Sources: SIFMA · DTCC/DTC · BCG · Standard Chartered.
Institutional Adoption Is Already Live
The evidence is not the forecast itself. It is the live activity already visible across market infrastructure, custody, tokenized funds and institutional settlement.
QVaR Glossary: Core Terms
- QVaR
- Quantum Value at Risk. An umbrella framework for Asset QVaR, Flow QVaR and Settlement QVaR.
- A-QVaR
- Asset Quantum Value at Risk. Standing economic value governed by a quantum-vulnerable cryptographic control surface after current vulnerability and deployed mitigation are applied.
- F-QVaR
- Flow Quantum Value at Risk. Quantum-critical transaction value passing through vulnerable cryptographic authorization over a defined horizon, expressed as $/day, $/month or another period.
- S-QVaR
- Settlement Quantum Value at Risk. Institution-specific value that can become economically exposed during the effective compromise-to-detection-to-containment and settlement window.
- QCE
- Quantum-Critical Exposure. Standing dollar value governed by a quantum-vulnerable control surface.
- QCF
- Quantum-Critical Flow. Transaction value passing through a quantum-vulnerable control surface during a defined period.
- CVF
- Current Vulnerability Factor. Ordinal factor for the current architecture and operational barriers around a classical cryptographic control. Higher means greater current exposure.
- DME
- Deployed Mitigation Effectiveness. Credit only for mitigation that is actually deployed and demonstrably reduces the affected quantum-vulnerable control surface.
- MRS
- Migration Readiness Score. Separate ordinal score for publicly evidenced progress toward post-quantum migration. A roadmap does not reduce current QVaR.
- LSF
- Loss Severity Fraction. Institution-specific fraction of attack-window flow that can become economically unrecoverable after limits, DvP/netting, reversibility, recovery and compromised-control scope.
- CRQC
- Cryptographically Relevant Quantum Computer. Quantum computer capable of practically breaking deployed cryptography at real-system scale.
- Gross A-QVaR
- Non-deduplicated Asset QVaR across independent control surfaces; the same underlying asset can appear more than once.
- End-to-end PQ
- All relevant authorization, identity, custody, consensus, privacy and settlement cryptographic dependencies have a verified PQ path without a defeating classical fallback.
QVaR Methodology: Asset, Flow and Settlement Exposure
Quantum Value at Risk is an umbrella financial-exposure framework, not conventional statistical market VaR. This edition does not claim a loss probability, confidence interval or CRQC arrival forecast. It separates three quantities that should never be collapsed into one number.
Current Vulnerability Factor (CVF)
CVF expresses the fraction of economic exposure that remains dependent on vulnerable classical cryptography after current operational barriers are considered. Higher values therefore indicate greater current cryptographic vulnerability.
| Current architecture | CVF | Interpretation |
|---|---|---|
| Single ECDSA EOA | 0.95 | One classical key controls the full authorization surface. |
| ECDSA multisig (2-of-3) | 0.80 | Thresholding improves operations; all signing primitives remain classically vulnerable. |
| ECDSA multisig (3-of-5+) | 0.70 | Higher threshold reduces operational exploitability but not the underlying quantum vulnerability. |
| MPC threshold ECDSA | 0.75 | Key shares are distributed, but the aggregate authorization primitive still relies on elliptic-curve hardness. |
| Hardware-backed multisig / HSM | 0.60 | Strong classical custody controls; the public authorization primitive remains classical. |
| Time-locked + multisig | 0.55 | Detection/response window reduces operational loss potential but does not make the signature PQ-safe. |
| Institutional-grade HSM + multisig + monitoring | 0.50 | Maximum operational defence in this scale without deployed PQ cryptographic remediation. |
Deployed Mitigation Effectiveness (DME)
Migration Readiness Score (MRS) — reported separately
| Migration status | MRS |
|---|---|
| No disclosed PQ migration plan | 0.00 |
| PQ assessment or intention stated publicly | 0.05 |
| PQ plan disclosed with timeline and scope | 0.15 |
| PQ implementation in progress / partial surfaces | 0.35 |
| PQ hybrid deployment across relevant surfaces | 0.65 |
| PQ-native across relevant surfaces without defeating classical fallback | 0.95 |
MRS is not a current-risk discount. It measures preparedness and future risk trajectory. Two systems using the same vulnerable signature primitive today can have different migration readiness while having the same current cryptographic exposure.
Canton Flow QVaR example
CVF: 0.80
Network-wide deployed PQ mitigation credited in this public model: 0.00
F-QVaR = $6T+ × 0.80 = $4.8T+ / month
Canton also reports $350B+ daily tokenized U.S. Treasury repo activity. On the same illustrative CVF basis, that is $280B+/day of vulnerability-adjusted flow. Do not add the daily and monthly values, and do not add Flow QVaR to Asset QVaR.
Settlement QVaR example
If a system processes $350B/day, a 30-minute gross activity window corresponds to approximately $7.29B of flow before applying CVF, deployed mitigation and the institution-specific Loss Severity Fraction. S-QVaR then adjusts for the actual compromised key/control scope, transaction limits, DvP/netting, finality, reversibility, detection, containment and recovery mechanisms.
Public QVaR inputs derive from issuer/market supply, fund/provider AUM, network asset footprint, custody disclosures/estimates and transaction-flow disclosures. Gross Asset QVaR can overlap across independent control surfaces by design. Broadridge DLR activity is not added to Canton Flow QVaR because it is an identifiable workflow within the Canton ecosystem and would create double counting.
The QVaR Register: Asset QVaR + Quantum-Critical Flow Across 28 Programmes
Stock-exposure rows report Asset QVaR. Canton reports Flow QVaR because the public metric is transaction throughput rather than unique assets outstanding. CVF measures current vulnerability; MRS is shown separately and does not reduce current A-QVaR/F-QVaR.
| # | Institution / Programme | Chain(s) | Economic exposure / flow | CVF | MRS | A-QVaR / F-QVaR | Primary exposure |
|---|---|---|---|---|---|---|---|
| Stablecoin Issuers — $212.2B Asset QVaR | |||||||
| 1 | Tether / USDT | Ethereum, Tron, + | 183.34 ↗ | 0.80 | 0.00 | 146.7 | Admin mint/burn/pause authority; architecture semi-opaque |
| 2 | Circle / USDC | Ethereum, Solana, + | 73.42 ↗ | 0.70 | 0.00 | 51.4 | Admin, mint, freeze, blacklist; known multisig |
| 3 | MakerDAO / DAI+USDS | Ethereum | 14.40 ↗ | 0.60 | 0.00 | 8.6 | Governance multisig; multi-collateral controls |
| 4 | Ethena / USDe | Ethereum | 4.12 ↗ | 0.80 | 0.00 | 3.3 | Minting/redemption authority; delta-neutral position keys |
| 5 | First Digital / FDUSD | Ethereum, BNB | 0.34 ↗ | 0.80 | 0.00 | 0.27 | Admin/mint authority |
| 6 | PayPal / PYUSD | Ethereum, Solana | 2.93 ↗ | 0.65 | 0.00 | 1.9 | Paxos-managed admin; institutional-grade ops |
| Tokenized Funds — $8.4B Asset QVaR | |||||||
| 1 | BlackRock-Securitize / BUIDL | Ethereum, Polygon, + | ~2.80 ↗ | 0.70 | 0.00 | 2.0 | Smart contract owner/admin; Securitize infra |
| 2 | Ondo Finance / OUSG + USDY | Ethereum, Solana, + | 2.52 ↗ | 0.75 | 0.00 | 1.9 | Token admin, redemption gating, compliance keys |
| 3 | Hashnote / USYC | Ethereum | ~2.80 ↗ | 0.75 | 0.00 | 2.1 | Token admin; yield distribution controls |
| 4 | Hamilton Lane | Polygon, Stellar | 0.60 | 0.70 | 0.00 | 0.4 | Fund admin; transfer restriction controls |
| 5 | Franklin Templeton / BENJI | Stellar, Polygon, + | 1.98 ↗ | 0.70 | 0.00 | 1.4 | Token admin; Stellar Ed25519 chain dependency |
| 6 | Superstate / USTB | Ethereum | 0.78 ↗ | 0.75 | 0.00 | 0.6 | Token admin; compliance and transfer controls |
| 7 | JPMorgan / JLTXX | Ethereum (Kinexys) | 0.10 ↗ | 0.55 | 0.00 | 0.06 | $100M JPMorgan launch investment; tokenized government money-market fund on Ethereum |
| Custody and MPC — $396.3B Asset QVaR | |||||||
| 1 | Coinbase Custody (Prime) | Multi-chain | 300 ↗ | 0.65 | 0.00 | 195.0 | Bitcoin ETF custody, institutional prime; ECDSA keys |
| 2 | Fireblocks | Multi-chain | ~150 | 0.75 | 0.00 | 112.5 | MPC-CMP; ECDSA threshold shares |
| 3 | Anchorage Digital | Multi-chain | ~50 | 0.70 | 0.00 | 35.0 | Federally chartered; ECDSA custody infra |
| 4 | BitGo | Multi-chain | ~40 | 0.70 | 0.00 | 28.0 | Multisig ECDSA; qualified custodian |
| 5 | Copper | Multi-chain | ~15 | 0.75 | 0.00 | 11.3 | ClearLoop MPC; ECDSA threshold |
| 6 | Komainu | Multi-chain | ~10 | 0.70 | 0.00 | 7.0 | Nomura/CoinShares JV; institutional MPC |
| 7 | Hex Trust | Multi-chain | ~8 | 0.75 | 0.00 | 6.0 | Licensed custodian; MPC ECDSA |
| 8 | Fordefi | Multi-chain | ~2 | 0.75 | 0.00 | 1.5 | MPC with policy engine; ECDSA threshold |
| Public Chains — $179.8B Asset QVaR + Canton $4.8T+/month Flow QVaR | |||||||
| 1 | Canton Network | Institutional L1 / Global Synchronizer | $6T+/month processed ↗ | 0.80 | 0.35 | $4.8T+/month | $6T+ monthly throughput; $350B+ daily tokenized U.S. Treasury repo; Flow QVaR is a rate, not unique assets |
| 2 | Ethereum | Mainnet | $177.48B ↗ | 0.80 | 0.05 | $141.98B | Distributed + represented RWAs + stablecoins; ECDSA accounts, BLS consensus and KZG/curve dependencies |
| 3 | Solana | Mainnet | $20.52B ↗ | 0.80 | 0.10 | $16.42B | Distributed + represented RWAs + stablecoins; Ed25519 user keys; PDAs off-curve; consensus remains classical |
| 4 | Avalanche | C-Chain | $13.56B ↗ | 0.80 | 0.00 | $10.85B | Distributed + represented RWAs + stablecoins; validator secp256k1 and subnet/admin dependencies |
| 5 | Arbitrum | L2 (Ethereum) | $5.18B ↗ | 0.80 | 0.00 | $4.14B | Distributed + represented RWAs + stablecoins; sequencer and bridge/admin cryptographic dependencies |
| 6 | Polygon PoS | Mainnet | $4.32B ↗ | 0.80 | 0.00 | $3.46B | Distributed + represented RWAs + stablecoins; validator ECDSA and bridge/admin dependencies |
| 7 | Stellar | Mainnet | $3.75B ↗ | 0.80 | 0.00 | $3.00B | Distributed + represented RWAs + stablecoins; classic accounts use Ed25519; PQ signer type is roadmap work |
Interpretation: public-chain stock rows use network asset footprint and report Asset QVaR. Canton reports $6T+ processed monthly and is therefore modeled as $4.8T+/month Flow QVaR at CVF 0.80. Broadridge's $351B/day DLR volume is a Canton workflow and is not added again. MRS is readiness information, not a current-risk discount.
Stablecoin Asset QVaR: $212.2B
Using September 1, 2026 circulating market-cap inputs, USDT carries $146.7B Asset QVaR and USDC $51.4B Asset QVaR. The six stablecoin issuers total $212.2B Asset QVaR. Public supply values are sourced inputs; CVF and Asset QVaR are modeled.
USDT is the largest stablecoin exposure at $146.7B Asset QVaR; USDC is $51.4B. The difference reflects the report’s current vulnerability factors applied to the September 1 supply values. Migration readiness is tracked separately and does not discount current exposure.
Under the GENIUS Act (enacted July 2025), payment stablecoin issuers must meet reserve, redemption, and disclosure requirements. No quantum-readiness requirement exists in the current framework. The GENIUS Act's permitted issuers collectively govern over $200 billion in circulating supply on ECDSA-dependent admin keys.
Custody and MPC Asset QVaR: $396.3B
Coinbase reports $300B assets under custody, producing $195.0B QVaR at CVF 0.65. The remaining custody exposure bases without exact public AUC are modeled estimates. Threshold MPC improves classical key-management resilience but does not make the underlying ECDSA signature primitive post-quantum secure.
Within custody, Coinbase Custody is the largest modeled exposure at $195.0B, followed by Fireblocks at $112.5B. Coinbase’s $300B custody figure is public; the other custody exposure bases marked with ~ are modeled estimates.
Is your custody provider in this register? EternaX PQ Custody SDK adds dual-gate SLH-DSA authorization beneath existing MPC, HSM, and multisig workflows. No provider replacement.
Scope a Custody PilotTokenized Fund Asset QVaR: $8.4B
Tokenized fund QVaR is smaller in absolute terms but carries distinct risk. Fund admin keys control investor compliance claims (accreditation, jurisdiction, transfer eligibility), NAV updates, and redemption gating. Compromise of these keys can simultaneously freeze redemptions, manipulate reported NAV, and bypass transfer restrictions. BlackRock's BUIDL at $2.0 billion and Ondo's combined OUSG/USDY at $1.8 billion represent the largest exposures. Franklin Templeton's BENJI on Stellar faces additional chain-level risk because Stellar's Ed25519 permanently exposes every account's public key.
The tokenized fund category is growing rapidly: total tokenized RWA AUM exceeded $31 billion by mid-2026, with BCG projecting $14 trillion by 2030 and $55 trillion by 2035, while Standard Chartered and Synpulse project $30.1 trillion by 2034. Every dollar of new issuance on ECDSA-dependent infrastructure compounds QVaR. The EternaX PQ-ONCHAINID, PQ-Permit, and PQ-4626 controls protect issuer authority, compliance claims, and vault governance on supported EVM deployments without requiring contract redeployment.
Network Asset & Flow QVaR: $179.8B Standing Exposure + $4.8T+/month Canton Flow
For public chains with observable stock value, this edition calculates Asset QVaR from network asset footprint. Ethereum’s $177.48B footprint produces $141.98B A-QVaR at CVF 0.80; Solana’s $20.52B footprint produces $16.42B A-QVaR. Migration-readiness scores remain visible but do not discount current exposure.
Flow QVaR is network-agnostic. Every network carrying economic transactions has quantum-critical flow. Canton is the lead institutional example because it publicly reports $6T+ processed monthly and $350B+ daily tokenized U.S. Treasury repo activity. At CVF 0.80 and DME 0.00, the report models $4.8T+/month F-QVaR. Flow is a rate, not unique assets outstanding, and it is never added to Asset QVaR.
Comparable Flow QVaR Examples
$6T+ monthly network throughput × 0.80 CVF. Canton separately reports $350B+ daily tokenized U.S. Treasury repo activity.
Primary source ↗$11.4B of Q2 2026 stablecoin transfer volume × 0.80 CVF. This is a different flow class and is not directly comparable to Canton institutional throughput.
Primary source ↗Top 15 Network Post-Quantum Readiness Benchmark
This section expands the protocol analysis to the first 15 networks in the supplied benchmark, preserving the exact source order: EternaX, Zcash, Canton Network, Ethereum, Solana, Arc, Tempo, Hyperledger Besu, Stellar, Starknet, Sui, Aptos, NEAR, Algorand, and XRP Ledger. The table is intentionally detailed evidence; the report-level hero charts above focus on the two findings with the highest institutional and media significance.
Open the full 15-network post-quantum readiness benchmark
| # | Network | Score | PQ Core | Transactions & Execution | Consensus & Finality | Privacy & Confidentiality | Full-Stack Crypto-Agility | Standards | Post-Quantum Compliance Readiness |
|---|---|---|---|---|---|---|---|---|---|
| 01 | EternaX | 93 | 3/3 INTERNAL TESTNET | PQ-safe · SLH-DSA · testnet | PQ-safe · testnet | PQ-safe · institutional privacy · testnet | Full-stack · independent scheme migration | FIPS 203 / 205 · finalized standards alignment | PQ standards aligned · module validation deployment-specific |
| 02 | Zcash | 50 | 0/3 | Current spend authorization remains classical; Ironwood quantum recoverability is live on mainnet | Not PQ-safe · no PQ consensus credited | Quantum recoverability live; recoverability ≠ PQ-safe authorization | NU6.3 Ironwood live; full PQ authorization migration not demonstrated | Ironwood Quantum Recoverability live since July 28, 2026 | Not end-to-end PQ; quantum recoverability is live |
| 03 | Canton Network | 62 | 0/3 | ML-DSA signing available behind experimental flag; production migration incomplete | Not PQ-safe · production crypto remains ECC | Not PQ-safe · strong privacy, but not PQ | Extensible crypto API; broader PQC implementation planned over 6–12 months | ML-DSA experimental now; broader signing/encryption migration planned | Not end-to-end PQ today; active native PQC migration |
| 04 | Ethereum | 56 | 0/3 | Not PQ-safe · production authorization today | Not PQ-safe · production consensus today | Not PQ-safe · no protocol-wide PQ privacy | Dedicated PQ team; Lean Ethereum roadmap targets core PQ infrastructure ~2029 | NIST-aware PQ roadmap; leanXMSS / leanVM work | Not end-to-end PQ today; active multi-layer migration |
| 05 | Solana | 52 | 0/3 | Ed25519 protocol transactions; Winternitz Vault is a deployed opt-in PQ primitive | Current consensus remains classical; Alpenglow introduces BLS, also not PQ | Not PQ-safe · public by default | Migration path researched; no protocol-wide PQ switch live | Evaluating Falcon and alternatives; no finalized protocol-wide FIPS-PQ scheme live | Not end-to-end PQ today; proactive migration work |
| 06 | Arc | 58 | 0/3 | SLH-DSA supported for developers/wallets today; core transaction signatures remain ECDSA | Not PQ-safe · validator PQ is future work | Not PQ-safe · privacy not PQ-durable | PQ developer/wallet path live; final PQ transaction signature not yet selected | FIPS 205 SLH-DSA support live; ECDSA remains transaction baseline | Not end-to-end PQ; public mainnet scheduled Sep. 16, 2026 |
| 07 | Tempo | 54 | 0/3 | Not PQ-safe · no PQ signature live | Not PQ-safe · no PQ consensus credited | Not PQ-safe · privacy not PQ-durable | Not full-stack · authentication interface only; no PQ stack migration demonstrated | No PQ standard live today | Not PQ compliant today · no PQ signature or KEX standard live |
| 08 | Hyperledger Besu | 38 | 0/3 | Not PQ-safe upstream · Ethereum transaction signatures | Not PQ-safe upstream · QBFT validator signing | Not PQ-safe by default · enterprise privacy ≠ PQ privacy | Not full-stack · upstream core PQ migration requires custom work | No upstream PQ standard today | Not PQ compliant upstream · native PQ transaction / QBFT baseline not present |
| 09 | Stellar | 37 | 0/3 | Not PQ-safe · Ed25519 accounts | Not PQ-safe · no PQ consensus credited | Not PQ-safe · public by default | Quantum Preparedness Plan: PQ verification in Soroban, then signer migration | ML-DSA-44 / ML-DSA-65 planned as Soroban host functions | Not PQ compliant today; PQ signer type is roadmap work |
| 10 | Starknet | 61 | 0/3 | Experimental Falcon-512 account demonstrated on mainnet | STARK proving is hash-based; full consensus stack not credited as PQ-safe | Not PQ-safe · public by default | Not full-stack · account/hash agility only; full PQ stack not demonstrated | Falcon / FIPS 206 pending · experimental / unaudited | Not end-to-end PQ; experimental account-level progress |
| 11 | Sui | 66 | 0/3 | ML-DSA-65 native accounts built; SLH-DSA vault path built; rollout pending | Not PQ-safe · no PQ consensus credited | Not PQ-safe · no PQ privacy rail credited | Crypto-agile account path; mainnet vaults targeted 2026, native ML-DSA accounts Q1 2027 | FIPS 204 ML-DSA-65 + FIPS 205 SLH-DSA selected | Not end-to-end PQ today; production rollout pending |
| 12 | Aptos | 56 | 0/3 | Not PQ-safe live · SLH-DSA feature-gated | Not PQ-safe · no PQ consensus credited | Not PQ-safe · public by default | Not full-stack · authorization path only; production stack migration not demonstrated | FIPS 205 path · not live mainnet auth | Not PQ compliant today · FIPS 205 path exists; live mainnet auth not credited |
| 13 | NEAR | 63 | 1/3 | ML-DSA account/access-key signing live | Consensus still classical; PQ consensus targeted by end-2027 | Not PQ-safe · no PQ privacy credited | Not full-stack · account/access-key agility only; consensus/privacy remain non-PQ | FIPS 204 account only · live at account/access-key level; not chain-wide | Partial PQ: FIPS 204 account-level support live |
| 14 | Algorand | 62 | 1/3 | Native Falcon-1024 accounts live on Mainnet since August 2026 | Consensus/VRF still includes classical ECC dependencies | Not PQ-safe · no PQ privacy credited | Native PQ accounts live; broader consensus/VRF migration underway | Falcon live; FN-DSA / FIPS 206 standardization still pending | Partial PQ: native account authorization live, full stack incomplete |
| 15 | XRP Ledger | 55 | 0/3 | secp256k1 / Ed25519 production signatures remain classical | Validator-level PQ testing/hybrid work underway | Not PQ-safe · confidential crypto not PQ-credited | Multi-phase roadmap with active testing; full transition targeted no later than 2028 | Testing NIST-recommended candidates; hybrid Devnet transition planned | Not PQ compliant today; full PQ readiness targeted by 2028 |
Source-order note: this table deliberately preserves the order supplied in the benchmark rather than re-ranking by score. “PQ Core” is the source's 3-layer coverage field. The statements above are source-derived benchmark assessments, not independently re-scored in this HTML.
Remediation path: PQ-native base infrastructure and settlement, PQ Custody SDK, PQ-ONCHAINID, PQ-Permit and PQ-4626 map directly to these control requirements. For Hyperledger Besu specifically, the next section separates existing-network hardening from a greenfield PQ-Safe Ledger path. Remediation is credited in QVaR only when controls are actually deployed.
Hyperledger Besu: From QVaR Exposure to a Deployable Post-Quantum Protection Boundary
The benchmark identifies standard Besu as a classical control surface across transaction authorization, validator signing, P2P/node credentials, privacy dependencies and custody workflows. EternaX provides two deployment paths: harden an existing Besu network without replatforming, or deploy a PQ-safe Besu stack from genesis.
Harden the live network without replacing it
Deploy PQ-Safe Ledger from genesis
Migration Readiness Gap: 26 of 28 Lack a Public End-to-End PQ Path
The core institutional finding is a migration-readiness gap. MRS measures preparedness and future risk trajectory; it does not reduce current Asset or Flow QVaR merely because an organization has announced a plan. NIST and EO timelines remain planning and scope signals as described below.
Scenario basis: the bars reproduce the report's earlier institution-level planning model as an illustrative schedule, not a forecast of when any institution will actually complete migration. Public roadmap information is reflected where available; all other bars are scenario assumptions used to visualize planning risk. MRS remains the report's formal readiness measure.
| Signal | What it actually means | Applicability |
|---|---|---|
| NIST IR 8547 | Initial Public Draft transition guidance; proposed deprecation/disallowance timelines vary by algorithm/security strength. | Planning guidance, not a universal private-sector statute. |
| EO 14412 | Federal HVAs/high-impact systems: PQ key establishment by 2030; PQ digital signatures by 2031. | Direct Federal scope; broader critical-infrastructure assistance. |
| FAR process | EO directs a proposed FAR rule for covered contractors to comply with applicable FIPS by end-2030. | Contractor obligations depend on the resulting rule and coverage. |
| FIPS 140-2 transition | FIPS 140-2 validations remain active through Sep. 21, 2026; only FIPS 140-3 validations remain active from Sep. 22. | Cryptographic-module validation transition; not itself a PQC deadline. |
Primary sources: NIST IR 8547 · Executive Order 14412 · NIST CMVP FAQ.
QVaR Verification Standard: Reproducible Evidence for Quantum Remediation
QVaR should not rely only on narrative claims. The strongest evidence package is a reproducible controlled test: deploy a representative classical control surface, demonstrate what compromised classical authorization permits, deploy the corresponding PQ-protected control, replay the same authorization attempt, and publish the code, configuration and verifiable transaction or protocol evidence.
| Step | Evidence required | Publication rule |
|---|---|---|
| 1. Classical setup | Open contract/configuration and exact cryptographic control surface. | Must be reproducible. |
| 2. Classical compromise demonstration | Transaction or protocol action demonstrating authority after key compromise. | Clearly labelled as a controlled test, not a real institution breach. |
| 3. PQ-protected setup | Same business function with documented PQ authorization layer. | Architecture and assumptions disclosed. |
| 4. Replay | Same unauthorized action rejected under PQ control. | Publish transaction hash/log or equivalent verifiable artifact. |
| 5. Mapping | Map only the verified control pattern to real deployments; do not claim identity of internal architecture unless publicly evidenced. | Confidence grade required. |
This section defines the verification standard. It does not claim that a live proof artifact is attached to this Q3 2026 report; only completed, reproducible artifacts should be labelled verified.
How to Reduce QVaR: Post-Quantum Remediation Paths
QVaR should connect directly to remediation. The remediation stack starts with the base infrastructure itself: transaction authorization, validator/consensus signing, cryptographic verification, privacy dependencies and upgrade paths must become post-quantum capable. Application-layer controls such as custody, identity, permits and tokenized-vault authorization then sit on top of that foundation.
| QVaR component | Control surface | Post-quantum remediation | Available today |
|---|---|---|---|
| PQ-safe base infrastructure | Transaction authorization, validator/consensus signing, cryptographic verification, privacy dependencies and upgrade paths are quantum-vulnerable or non-agile. | EternaX PQ-native base infrastructure / settlement layer — signature-agile PQ authorization, PQ-ready verification and settlement primitives designed to remove classical single points of cryptographic failure. | |
| Admin key authority | Mint, burn, pause, upgrade, proxy owner | Dual-gate PQ authorization: SLH-DSA identity anchor + signature-agnostic threshold, layered beneath existing custody | EternaX PQ Custody SDK |
| Compliance claims | KYC/AML assertions, investor accreditation, ONCHAINID | PQ-safe claim issuance: SLH-DSA-signed claims verified on-chain via PQ precompile | EternaX PQ-ONCHAINID |
| Permit/approval authority | ERC-2612 permit, delegated approvals | PQ-safe permit signatures replacing ECDSA EIP-712 | EternaX PQ-Permit |
| Vault governance | ERC-4626 admin, deposit/withdraw, yield | PQ-safe vault authorization with SLH-DSA admin verification | EternaX PQ-4626 |
| MPC custody keys | ECDSA threshold shares across MPC nodes | PQ authorization gate before MPC signing gate; existing provider preserved | EternaX PQ Custody SDK |
| Settlement infra | Validator keys, consensus, finality | PQ-native chain: SLH-DSA accounts, SILMARILS auth, ~2% TPS overhead | EternaX Pluto / PQ Besu |
| Immutable contracts | Frozen standards, non-upgradeable DeFi | No remediation; assets must migrate to PQ-safe infrastructure | No provider |
Illustrative Asset QVaR Reduction: From $3.5B to $1.225B
Illustrative example: a $5B programme with CVF 0.70 and DME 0.00 produces $3.5B Asset QVaR. If deployed, verified PQ remediation achieves DME 0.65 while QCE and CVF remain constant, A-QVaR becomes $1.225B — an exact 65% reduction. A roadmap alone would increase MRS, not reduce current A-QVaR.
Turn Your QVaR Findings Into a Remediation Plan
Start with a pilot scoping call to map the highest-value cryptographic control surfaces and define a deployable remediation path. Institutions already ready to share settlement and control data can proceed to a confidential Settlement QVaR assessment.
Book a Pilot CallFrequently Asked Questions: QVaR, Post-Quantum Security & Institutional Digital Assets
Last reviewed: September 8, 2026. These answers are written to stand alone for readers, search engines and AI retrieval systems. Time-sensitive network, regulatory and institutional claims should be read with the dated primary evidence in the report and Sources section.
These answers are concise and self-contained so boards, technical teams, journalists, search engines and AI systems can extract the report's definitions and conclusions without losing the methodology caveats.
Core QVaR Definitions & Institutional Exposure
What is Quantum Value at Risk (QVaR)?
Quantum Value at Risk (QVaR) is a framework for measuring post-quantum cryptographic financial exposure. It separates Asset QVaR, Flow QVaR and Settlement QVaR so institutions can distinguish standing value, transaction throughput and attack-window settlement exposure.
How is QVaR different from traditional financial Value at Risk (VaR)?
Traditional financial VaR estimates potential market loss over a defined time horizon and confidence level. QVaR is not statistical market VaR: it measures quantum-related cryptographic exposure and control effectiveness so institutions can compare control surfaces and prioritize post-quantum migration.
What is Quantum-Critical Exposure (QCE)?
Quantum-Critical Exposure (QCE) is the standing dollar value governed by a quantum-vulnerable cryptographic control surface before the Current Vulnerability Factor and deployed mitigation are applied. Depending on the programme, QCE can be circulating supply, AUM, custody assets, network asset footprint or another clearly identified value base tied to cryptographic authority.
How is Asset QVaR, Flow QVaR and Settlement QVaR calculated?
Asset QVaR uses A-QVaR = QCE × CVF × (1 − DME). Flow QVaR uses F-QVaRₕ = QCFₕ × CVF × (1 − DME), where QCF is quantum-critical flow over horizon h. Settlement QVaR additionally applies the effective attack/settlement window and institution-specific loss severity. Migration Readiness Score (MRS) is reported separately and does not reduce current QVaR merely because a roadmap exists.
What does the $796.7 billion Asset QVaR headline mean?
$796.7 billion is the modeled gross, non-deduplicated Asset QVaR across the scored standing-exposure categories in the Q3 2026 register: stablecoins, tokenized funds, custody/MPC and public-chain exposure. It is a vulnerability-adjusted exposure measure, not a forecast that $796.7 billion will be lost in a quantum attack.
Is the $796.7 billion Asset QVaR figure unique assets at risk?
No. Gross Asset QVaR is intentionally non-deduplicated because the same underlying asset can depend on multiple independent cryptographic control surfaces. It measures modeled control-surface exposure, not unique assets or expected loss.
Why does the QVaR report reference a $318.5 trillion capital-market base?
SIFMA reports $157.8 trillion of global equity market capitalization and $160.7 trillion of global fixed-income securities outstanding for 2025, or $318.5 trillion combined. QVaR uses this only as addressable capital-market context for institutional tokenization, not as current on-chain or quantum-exposed value.
Primary source: SIFMA 2026 Capital Markets Fact Book findings
Is $318.5 trillion already on-chain or guaranteed to be tokenized?
No. The report explicitly does not claim the entire $318.5 trillion capital-market base is already on-chain or will be tokenized by a particular date. The point is that tokenization can progressively place larger portions of financial-market infrastructure under cryptographic controls.
Are USDT, USDC and other major stablecoins quantum-safe today?
Major stablecoins are not automatically end-to-end post-quantum safe because minting, burning, pausing, freezing, blacklisting, upgrades and treasury controls can depend on classical ECDSA or EdDSA authorization and on the security of the underlying chain. A stablecoin should only be described as end-to-end PQ-safe when every material control surface and dependency has verified post-quantum protection.
Does MPC or threshold custody make ECDSA quantum-safe?
No. MPC and threshold signing can materially improve classical key-management resilience, but they do not change the post-quantum security of the underlying ECDSA signature primitive. A threshold ECDSA system remains dependent on elliptic-curve hardness unless a post-quantum authorization path is added.
Post-Quantum Readiness by Network
Is Ethereum quantum-safe?
Ethereum is not end-to-end post-quantum today. The Ethereum Foundation has a dedicated PQ team and a structured Lean Ethereum roadmap targeting core post-quantum infrastructure around 2029.
Primary source: Ethereum.org
Is Solana quantum-safe?
Solana is not end-to-end post-quantum today. Protocol transactions use Ed25519; PDAs are off-curve and have no private keys. The Solana Foundation identifies the Winternitz Vault as a deployed quantum-resistant primitive and describes a broader migration path, but no protocol-wide PQ signature migration is live.
Primary source: Solana Foundation
Is the Canton Network post-quantum safe today?
Canton is not end-to-end post-quantum safe today. Canton reports $6T+ processed monthly and $350B+ daily tokenized U.S. Treasury repo activity; this report uses the explicitly time-bounded monthly throughput for Flow QVaR. Digital Asset states that ML-DSA signing is available behind an experimental flag and broader PQC migration is underway.
Primary source: Canton Network Forum / Digital Asset
Is Hyperledger Besu post-quantum safe, and how can Besu be remediated?
Stock Hyperledger Besu is not an end-to-end post-quantum transaction, consensus, P2P and privacy stack. Existing Besu networks can add PQ privacy, tokenization and custody controls incrementally, while a greenfield PQ-safe ledger can extend protection into validator signing, P2P/node identity, native transaction authorization and privacy. The report maps these Besu control surfaces to EternaX remediation components.
Primary source: Hyperledger Besu QBFT documentation
Is Zcash quantum-safe?
Zcash is not end-to-end post-quantum today. Ironwood NU6.3 activated on mainnet July 28, 2026 and makes Ironwood-pool funds quantum-recoverable, but quantum recoverability is not the same as PQ-safe transaction authorization.
Primary source: Zcash NU6.3
What is the difference between quantum recoverability and quantum-safe authorization?
Quantum-safe authorization aims to prevent a quantum adversary from forging or taking over current authorization. Quantum recoverability focuses on restoring or reclaiming control after a cryptographic failure event. A system can make progress on recoverability while current transaction signatures remain classically vulnerable.
Regulatory & Migration Timelines
Does NIST IR 8547 create a universal 2030 post-quantum deadline?
No. NIST IR 8547 is an Initial Public Draft, not a universal private-sector law. Its proposed transition guidance distinguishes algorithm families and classical security strengths, so institutions should treat the 2030/2035 dates as important migration-planning signals rather than one blanket legal deadline for every blockchain programme.
Primary source: NIST IR 8547 Initial Public Draft
What does Executive Order 14412 require for post-quantum migration?
Executive Order 14412 requires specified U.S. Federal high-value assets and high-impact systems to use post-quantum cryptography for key establishment by December 31, 2030 and digital signatures by December 31, 2031. It also directs a separate FAR rulemaking process for covered contractors.
Primary source: Executive Order 14412
Is the September 2026 FIPS 140-2 transition a post-quantum deadline?
No. The FIPS 140-2 transition is a cryptographic-module validation transition, not itself a post-quantum migration deadline. FIPS 140-2 validations remain active through September 21, 2026, after which the active CMVP programme moves to FIPS 140-3 validations.
Primary source: NIST CMVP FAQ
Remediation, Verification & Evidence
How can an institution reduce Asset QVaR, Flow QVaR and Settlement QVaR?
An institution reduces current QVaR by deploying controls that actually reduce the vulnerable cryptographic surface: post-quantum transaction authorization, validator or consensus signing, verification, privacy, custody, identity/compliance and settlement controls. A roadmap improves Migration Readiness Score but does not reduce current QVaR until mitigation is deployed.
Can post-quantum protection be added without replacing the custody provider or blockchain?
Sometimes. A PQ authorization or policy gate can be added around existing custody, tokenization or privacy workflows without replacing the underlying provider or chain. That protects the covered control surface but does not automatically remove quantum exposure in unchanged chain-level, validator-level or outer authorization dependencies.
What is the QVaR Verification Standard?
The QVaR Verification Standard requires reproducible evidence rather than narrative claims: demonstrate a representative classical control surface in a controlled test, show what compromised classical authorization permits, deploy the corresponding PQ-protected control, replay the same action, and publish the code, configuration and verifiable transaction or protocol evidence.
How often should the Quantum Value at Risk Register be updated?
The QVaR Register is designed as a quarterly research series. Each edition should refresh AUM, supply, custody, network and flow inputs; cryptographic architecture evidence; deployed mitigation; migration readiness; overlap treatment; confidence grades; and methodology changes.
Can an institution challenge or correct its QVaR assessment?
Yes. A named institution can submit primary evidence that materially changes its architecture, exposure input, control-surface mapping, deployed mitigation or migration-readiness assessment. Accepted changes should be reflected in the next edition with a transparent methodology change log.
What do QVaR evidence grades A, B and C mean?
Grade A means primary evidence such as on-chain code, protocol specifications, regulatory filings, issuer attestations or official technical documentation. Grade B means official provider disclosure or high-quality secondary evidence where implementation is not independently inspectable. Grade C means estimated exposure, inferred architecture or market-share analysis and should carry explicit uncertainty.
Network Benchmark: Additional Protocols
Is Arc post-quantum safe?
Arc is not end-to-end post-quantum today. Circle states Arc already supports SLH-DSA for developers and wallets, while core transaction signatures remain ECDSA. Public mainnet is scheduled for September 16, 2026.
Primary source: Circle
Is Tempo post-quantum safe?
In the supplied benchmark, Tempo scores 54 and receives 0/3 core PQ coverage today. No live PQ signature, PQ consensus or PQ-durable privacy layer is credited, and the authentication interface is not treated as full-stack migration.
Is Stellar post-quantum safe?
In the supplied benchmark, Stellar scores 37 and receives 0/3 core PQ coverage today. Ed25519 accounts remain classical, no PQ consensus layer is credited, and public-by-default operation does not provide PQ confidentiality.
Is Starknet post-quantum safe?
In the supplied benchmark, Starknet scores 61 but receives 0/3 full-layer PQ coverage. A Falcon-512 account demonstration is treated as experimental, and STARK proving is not treated as equivalent to end-to-end PQ-safe consensus, privacy and transaction authorization.
Is Sui post-quantum safe?
Sui is not end-to-end post-quantum today. Sui has built ML-DSA-65 native accounts and an SLH-DSA vault path; quantum-safe vaults are targeted for Mainnet in 2026 and native ML-DSA account authentication for Mainnet in Q1 2027.
Primary source: Sui
Is Aptos post-quantum safe?
In the supplied benchmark, Aptos scores 56 and receives 0/3 live PQ core coverage. The SLH-DSA path is feature-gated rather than live mainnet authorization, and consensus/privacy are not credited as PQ-safe.
Is NEAR post-quantum safe?
NEAR has live ML-DSA account/access-key signing. Consensus remains classical and NEAR targets post-quantum consensus by the end of 2027. The benchmark therefore gives NEAR partial 1/3 coverage.
Primary source: NEAR
Is Algorand post-quantum safe?
Algorand has native Falcon-1024 accounts live on Mainnet since August 2026 and Falcon-based State Proofs, but consensus and VRF dependencies are not yet fully post-quantum. The benchmark therefore gives Algorand partial 1/3 coverage.
Primary source: Algorand
Is XRP Ledger post-quantum safe?
XRPL is not post-quantum today. Ripple is actively testing quantum-resistant cryptography and hybrid migration paths and targets full post-quantum readiness no later than 2028.
Primary source: Ripple
Institutional Adoption & Market Infrastructure
Why is DTCC important to Quantum Value at Risk (QVaR)?
DTC currently custodies more than $114 trillion of assets. DTCC processed live production trades using DTC-tokenized assets with about 40 participating firms in July 2026 and plans to launch the DTC Tokenization Service in October 2026. The significance for QVaR is that tokenization is moving into core market infrastructure, increasing the value dependent on cryptographic control surfaces.
Primary source: DTCC
How much institutional tokenized repo and collateral flow is already live?
Broadridge reported that its Distributed Ledger Repo platform processed $351 billion in average daily repo transactions and $7.4 trillion of total volume in August 2026. DLR is a live institutional tokenized financing and collateral workflow within the Canton ecosystem and is therefore relevant evidence for Flow QVaR, but it is not added again to Canton Flow QVaR.
Primary source: Broadridge
How large is BlackRock's institutional digital-asset footprint?
BlackRock states that it has nearly $150 billion in AUM connected to digital assets, including the world's largest tokenized treasury fund, approximately $65 billion of stablecoin reserves and nearly $80 billion of digital-asset ETPs. The figure is institutional-adoption context, not a standalone QVaR calculation.
Primary source: BlackRock
Advanced QVaR Framework Questions
What are Asset QVaR and Flow QVaR, and how are they different?
Asset QVaR measures standing economic value governed by vulnerable cryptographic controls and is expressed in dollars at a point in time. Flow QVaR measures vulnerability-adjusted quantum-critical transaction throughput over a defined period such as dollars per day, quarter or month. Because their units differ, Asset QVaR and Flow QVaR must not be added together.
Why does the report use Canton for Flow QVaR rather than adding $6T to Asset QVaR?
Canton explicitly publishes a $6T+ processed-monthly metric, so this report uses that time-bounded figure as transaction throughput for Flow QVaR rather than silently treating it as unique assets outstanding. Canton also uses $6T+ tokenized-RWA language elsewhere, which is why the report keeps the flow and stock interpretations separate unless the underlying asset-inventory definition is independently reconciled.
Why does Migration Readiness Score (MRS) not reduce current QVaR?
A migration roadmap does not change the cryptographic primitive protecting transactions today. MRS therefore measures preparedness and future risk trajectory, while only Deployed Mitigation Effectiveness (DME) can reduce current Asset or Flow QVaR in the model.
What is Settlement QVaR, and what data is needed to calculate it?
Settlement QVaR estimates the value that can become economically exposed during a defined compromise-to-detection-to-containment and settlement window. It requires institution-specific data such as transaction limits, compromised key/control scope, finality, DvP or netting, reversibility, monitoring, detection and containment time, recovery mechanisms and loss severity.
Evidence Standard and Confidence Grades
Named-institution scoring is only useful if a third party can reproduce the inputs. Each future row-level evidence page should expose the dated AUM/supply/flow source, cryptographic architecture source, CVF rationale, any deployed mitigation evidence, separate MRS evidence, overlap treatment and calculation. Named institutions may submit primary evidence that materially changes an architecture, exposure input or migration-readiness assessment; accepted changes should be reflected in the next quarterly edition with a transparent methodology change log.
| Grade | Evidence quality | How it should be used |
|---|---|---|
| A | Primary on-chain code, protocol specification, regulatory filing, issuer attestation, or official technical documentation. | Can support direct factual statement. |
| B | Official provider disclosure or high-quality secondary source, but internal implementation is not independently inspectable. | Use with scope caveat. |
| C | Estimated AUM, inferred architecture, or market-share analysis. | Use range/tilde and avoid false precision. |
How to Cite This Report
Primary Sources, Data Inputs and Related EternaX Research
Standards / regulation: NIST IR 8547; EO 14412; NIST CMVP. Capital markets: SIFMA; DTCC/DTC; BCG; Standard Chartered. Market inputs: CoinGecko historical data; Superstate; Franklin Templeton; Coinbase Institutional; DefiLlama; Broadridge. Protocol sources: Ethereum; Solana; Canton; Arc; Zcash; Sui; NEAR; Algorand; XRPL. Institutional activity: DTCC live production trades; DTCC working group / DTC custody; Broadridge DLR; BlackRock 2026 Chairman’s Letter; Franklin Templeton BENJI; Coinbase Institutional. Network exposure: RWA.xyz network metrics; Canton Network flow metrics.
QVaR is a risk-quantification methodology developed by EternaX Labs. It is a vulnerability-adjusted exposure index, not a prediction of loss and not conventional statistical market VaR. Actual exploitation depends on CRQC capability, cryptographic details, public-key exposure, operational controls and response conditions. Scores are intended to be updated quarterly with a public change log. Next edition: Q4 2026 (December).
Related EternaX research: Already Broken Q1 2026 · Cryptographic Migration Debt · Exposure Map 2026 · Signature Security Ranking · MPC Custody Crisis · Non-Upgradeable Chains · Readiness Benchmark 2026 · Besu Quantum Risk